Multi Apache Polaris Flaws Granting Unauthorized Multi-Cloud Access
ID: 8d9bf98e-d4d6-59a2-8489-c7005947725c
STIX ID: report--8d9bf98e-d4d6-59a2-8489-c7005947725c
Feed Name: securityonline.info
Apache Polaris released a security update (1.4.1) addressing four important vulnerabilities that let authenticated low-privileged users obtain delegated cloud storage credentials for attacker-controlled locations, potentially enabling reading, listing, creating, or deleting data across AWS S3 and Google Cloud Storage. The flaws (CVE-2026-42809 through CVE-2026-42812) stem from premature credential vending, unescaped wildcard and quote characters in resource restrictions, and a metadata-path validation bypass; administrators are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
